CVE-2020-14974: High severity iobit unlocker vulnerability
Published Jun 23, 2020
·Updated
The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124.
Affected Software
1 affected component
IObit IOBit Unlocker=1.1.2
Remediation
Patch Available
Event History
Jun 23, 2020
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-14974?
The severity of CVE-2020-14974 is high with a severity value of 7.1.
2
Which software version is affected by CVE-2020-14974?
IOBit Unlocker 1.1.2 is affected by CVE-2020-14974.
3
What can a low-privileged user do with CVE-2020-14974?
A low-privileged user can use CVE-2020-14974 to unlock a file and kill processes, even ones running as SYSTEM, that hold a handle.
4
How can I fix CVE-2020-14974?
To fix CVE-2020-14974, it is recommended to update to the latest version of IOBit Unlocker.
5
Where can I find more information about CVE-2020-14974?
You can find more information about CVE-2020-14974 at the following references: - [The Evil Bit Blog](https://theevilbit.github.io/posts/) - [IOBit Unlocker Official Website](https://www.iobit.com/en/iobit-unlocker.php)